Installation

Splunk Universal Forwarder agent support for Amazon Linux 2023 x86/arm

vk2
New Member

Is splunk forwarder agent 9.2.0.1 supported on Amazon Linux 2023 x86/arm OS using RPM file. 

Got error while starting splunk service. 
tcp_conn_open_afux ossocket_connect failed with No such file or directory
tcp_conn_open_afux ossocket_connect failed with No such file or directory
tcp_conn_open_afux ossocket_connect failed with No such file or directory

Labels (1)
Tags (2)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

UFs are supported on a relatively wide range of equipment and OS versions (and even if the current UF doesn't support your older hardware or OS release you can still use an older version of UF within the compatibility boundaries - and sometimes even beyond that but I wouldn't advise running UFs that old anyway).

if I'm not mistaken, the error is from the service trying to connect to a running splunkd instance.

Check your splunkd.log to see what's going on.

Also - how did you install that forwarder? RPM? Or just unpacked the tgz?

0 Karma

kiran_panchavat
SplunkTrust
SplunkTrust

@vk2 You can check the below document, Splunk universal forwarder is compatible with Linux OS which is having kernel 4.x or higher. If you have kernel 3.x , Splunk supports this platform and architecture, but might remove support in a future release. 

https://docs.splunk.com/Documentation/Splunk/latest/Installation/Systemrequirements#Confirm_support_... 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

    Thursday, June 25, 2026  |  11AM PDT / 2PM EDT  Duration: 1 Hour (Includes live Q&A) Register to ...

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...